3) Generation of Network Security Situation
The generation of network security situation refers to the
correlation of network security events, construction of
network security situation graph, and assessment of the
global network security situation. Net-SSA periodically
update the network security situation graph based upon the
security situation data calculated from event fusion and
correlation. After certain alert event is processed and
inserted into evidence base, Net-SSA schedules and
activates the associated rules and launches the process of
situation correlation, and correlates the security situation by
using above mentioned knowledge discovery algorithms. If
the correlation results indicate certain type of security
attack, then the network security situation graph is
dynamically updated in accordance of system settings, and
notifies the network security administrator.